Vulnerability Name: | CVE-2003-0834 (CCN-13605) | ||||||||
Assigned: | 2003-11-04 | ||||||||
Published: | 2003-11-04 | ||||||||
Updated: | 2018-05-03 | ||||||||
Summary: | Buffer overflow in CDE libDtHelp library allows local users to execute arbitrary code via (1) a modified DTHELPUSERSEARCHPATH environment variable and the Help feature, (2) DTSEARCHPATH, or (3) LOGNAME. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: SGI Type: UNKNOWN 20040801-01-P Source: HP Type: UNKNOWN HPSBUX0311-297 Source: MITRE Type: CNA CVE-2003-0834 Source: CCN Type: SA10144 Multiple Vendor CDE libDtHelp Buffer Overflow Vulnerability Source: CCN Type: SA10226 Sun Solaris CDE DtHelp Library Privilege Escalation Vulnerability Source: CCN Type: SA10352 HP Tru64 UNIX CDE libDtHelp Privilege Escalation Vulnerability Source: CCN Type: SA12216 SGI IRIX CDE Multiple Vulnerabilities Source: CCN Type: SA8874 HP Tru64 Unspecified CDE Buffer Overflow Vulnerabilities Source: CCN Type: SA8970 HP-UX Unspecified CDE Buffer Overflow Vulnerabilities Source: CCN Type: SECTRACK ID: 1008101 CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: SECTRACK ID: 1008103 (SCO Issues Fix) Re: CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: SECTRACK ID: 1008104 (Xi Graphics Issues Fix for DeXtop CDE) Re: CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: SECTRACK ID: 1008127 (Sun Issues T-Patches) Re: CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: SECTRACK ID: 1008216 (HP Issues Fix) CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: SECTRACK ID: 1008366 (HP Issues Fix for Tru64) CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: SECTRACK ID: 1008714 CDE libDtSvc Buffer Overflow Yields Root Access to Local Users Source: CCN Type: SECTRACK ID: 1008986 (Sun Issues Fix) CDE libDTHelp Buffer Overflow Lets Local Users Execute Arbitrary Code With Root Privileges Source: CCN Type: Sun Alert ID: 57414 Buffer Overflow Vulnerability in the CDE DtHelp Library May Allow Unauthorized "root" Access Source: SUNALERT Type: UNKNOWN 57414 Source: CCN Type: CIAC Information Bulletin O-020 Sun Buffer Overflow Vulnerability in the CDE DtHelp Library Source: IDEFENSE Type: UNKNOWN 20040825 CDE libDtHelp LOGNAME Buffer Overflow Vulnerability Source: CCN Type: US-CERT VU#575804 CDE libDtHelp vulnerable to buffer overflow via DTHELPUSERSEARCHPATH or DTHELPSEARCHPATH Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#575804 Source: CCN Type: OSVDB ID: 9186 CDE libDtHelp LOGNAME Local Overflow Source: CCN Type: BID-13757 Sun CDE DtSvc Unspecified Buffer Overflow Vulnerability Source: CCN Type: BID-13758 Sun CDE DtSvc DTDataBaseSearchPath Buffer Overflow Vulnerability Source: CCN Type: BID-7713 Multiple HP Tru64 Unspecified CDE Privilege Escalation Vulnerabilities Source: CCN Type: BID-7721 HP Tru64 CDE DTAppGather Unspecified Privilege Escalation Vulnerability Source: BID Type: Patch, Vendor Advisory 8973 Source: CCN Type: BID-8973 CDE LibDTHelp DTHelpUserSearchPath Local Buffer Overflow Vulnerability Source: XF Type: UNKNOWN cde-libdthelp-bo(13605) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:5141 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |